
Everybody loves cookies, most people know what they are on the web too, but they cause headaches for marketers due to their treatment of analytics.
The big question is should you implement a cookie consent option?

The answer, for most US small businesses, is probably yes but you may not be required to.
It largely comes down to the combination of technologies, use of tracking for marketing and the jurisdictions you operate in.
Also – I want to talk about the elephant in the room which is that an IP address can be treated as personally identifiable information (PII).
Whether an IP address should be considered personally identifiable information remains a debated topic. While GDPR generally treats IP addresses as personal data in many contexts, many technologists argue that an IP address alone rarely identifies a specific individual without additional information.
So as I write this, sitting in Woodbury, Minnesota here is my IP. I mean, thats clearly me right?
Anyone knows that 98.46.112.198 is Trev sitting in an office in Woodbury MN, not that its a Google data center in Mountain View, California.
I mean this IP address really gives me away!
I used Whats My IP Address for this check

Opt In vs Opt Out
One of the big distinctions in the regulations is whether someone should opt in or opt out. In the US it is typically either opt out or not required, whereas in Europe (UE & EEA) it is exclusively Opt In.
There are big differences in those settings.
Opt In is more restrictive than Opt Out so if you require users to Opt In you will lose a lot of tracking data. Having the option to Opt Out satisfies many concerns and is less restrictive giving a more complete analytics tracking picture but it does not cover all options and areas.
You can check your cookie compliance using a tool like this one from Cookie Bot.
Privacy Policy
You should have a privacy policy as part of a generally accepted level of expectation and site quality.
At a minimum, it should say what you do with data and how you treat it.
NOTE: In some industries, there may be specific levels and designations for handling data, such as HIPAA for health care.
Its better still if you list the technologies used for tracking and analytics and what they are and how they deal with data.
Rules and Regulations
The rules and regulations around cookie policy depend greatly on the use of technology with specific concern paid to tracking and remarketing use. The geographical location and legalities in different jurisdictions also have a significant impact on what cookie policy applies and how you have to handle it.
Different handling can cause significant effects on your analytics data. In the screen shot below around April 12th a full GDPR compliant policy was applied globally. Then around June 21st a more applicable US based GPC policy was applied with US state applicability settings.
The general traffic level of this site did not change significantly, and this was verified with a correlation analysis using Google Search Console data.

GPC (Global Privacy Control)
GPC – Global Privacy Control is a browser setting that lets users opt out. Honoring GPC signals can help satisfy universal opt-out requirements in several US state privacy laws, but it is only one component of an overall privacy compliance program.
US States that require GPC
- California
- Colorado
- Connecticut
- Delaware
- Maryland
- Minnesota
- Montana
- Nebraska
- New Hampshire
- New Jersey
- Oregon
- Texas
General Data Protection Regulation – GDPR
GDPR, the General Data Protection Regulation, is applicable in Europe and is one of the more restrictive regulations. When this is applied much of your analytics and tracking will not work if you are compliant. This leaves a big analytics hole in your data.
GDPR requires strict Opt in and user consent set explicitly with options to chose what not to allow. This is possibly the most stringent of consent requirements relating to use of cookies.
California Consumer Privacy Act (CCPA)
CCPA, the California Consumer Privacy Act, is California’s version of GDPR and is similarly restrictive. This applies to companies that do business in California and meet certain revenue and other thresholds. It focuses more on the use of personal data and what businesses do with them, requiring an option for users to state “do not sell my data”.
Consent Management Platform CMP
These regulations are tough to navigate, thats why it makes a lot of sense for most businesses to use a Consent Management Platform (CMP). This manages the layer between your website, the cookies it uses and the users of your website and their web browser. You install the CMP, chose applicable settings and let it manage it for you. We use Cookie Yes as our CMP.
Implementation Tiers
For more specifics on your type of site, you can refer to the table below and get a better idea on what you need to have covered.
| Business Type | Privacy Policy | Cookie Policy | Cookie Banner | Consent Manager (CMP) | GPC Support | Notes |
|---|---|---|---|---|---|---|
| Local SMB | ✅ Required | ✅ Recommended | ⚠️ Usually Not Required | ❌ Usually No | ✅ Recommended | Most Minnesota SMBs fall here. |
| Therapy / Healthcare Practice | ✅ Required | ✅ Recommended | ⚠️ Depends | ⚠️ Recommended | ✅ Recommended | HIPAA doesn’t require cookie banners, but healthcare sites attract more scrutiny. |
| National Lead Generation Site | ✅ Required | ✅ Required | ✅ Recommended | ✅ Recommended | ✅ Recommended | Especially if using Meta, LinkedIn, Google Ads, call tracking. |
| E-commerce Store | ✅ Required | ✅ Required | ✅ Recommended | ✅ Recommended | ✅ Recommended | Higher exposure to state privacy laws and advertising data use. |
| SaaS / B2B Software Company | ✅ Required | ✅ Required | ⚠️ Usually Recommended | ⚠️ Recommended | ✅ Recommended | Depends heavily on marketing stack and traffic sources. |
| Multi-State Enterprise | ✅ Required | ✅ Required | ✅ Recommended | ✅ Recommended | ✅ Recommended | Easier to standardize compliance nationally. |
| EU/UK Traffic (Any Business) | ✅ Required | ✅ Required | ✅ Required | ✅ Required | N/A | GDPR requires prior consent for non-essential cookies. |
| Publishing / Media Site | ✅ Required | ✅ Required | ✅ Recommended | ✅ Recommended | ✅ Recommended | Ad-tech ecosystem creates significant obligations. |
FAQs
Do I need a cookie consent banner on my website?
If you are a small business the answer is usually no, but there are some checks and considerations you need to have done before just discarding it. Many businesses should have a cookie consent banner and a privacy policy.
Is a privacy policy required for my website?
A privacy policy is usually required for most sites. Even if it is a boilerplate generic privacy policy, this is usually required to run ads and adds a level of trust when you have one.
What is the difference between Opt In and Opt Out cookie consent?
The difference is as the name sounds, with Opt out you are implicitly accepting them and without any action you have technically given consent. With opt in requirements cookies are not used or loaded until you explicitly opt in and allow their use.
These two distinctions have a significant impact on the type of use and tracking visibility you have.
What is Global Privacy Control (GPC)?
Global Privacy Control is a browser level opt out instruction that tells a website whether or not the user consents to storing of cookies and provides an opt out instruction automatically. This is required in several US states.
Which US states require businesses to honor GPC signals?
The US States that require GPC are;
- California
- Colorado
- Connecticut
- Delaware
- Maryland
- Minnesota
- Montana
- Nebraska
- New Hampshire
- New Jersey
- Oregon
- Texas
Does GDPR apply to businesses outside of Europe?
Yes, although GDPR is a European regulation it applies to any business that processes data of a person in the EU (European Union) or indeed the EEA (European Economic Area). Under the provision of the extraterritorial effect it regulates non EU businesses handling data in the EU or EEA. The CCPA, the California Consumer Privacy Act is very similar and applies in California only in the USA.
What is the California Consumer Privacy Act (CCPA)?
The CCPA, the California Consumer Privacy Act is very similar to GDPR but applies to California and focuses more on the sale of personal data.
Is an IP address considered personally identifiable information (PII)?
This is a somewhat nebulous concept and there are several cases where this has been upheld either in part or in full. There is not one single over riding rule or regulation that dictates an IP address as PII.
What is a Consent Management Platform (CMP)?
A consent management platform or CMP is a system that handles the interaction between a website, the cookies it intends to use and the requesting web browser. This is the familiar cookie pop up banner in play, where the CMP handles the regulations, jurisdictions, browser settings and user choices.
What cookies require user consent?
The types of cookies that require consent are typically;
- Analytics
- Tracking
- Personalization
- Social Media
- Retargeting
Do Google Analytics cookies require consent?
Typically as an analytics cookie yes. This is especially the case in the EU and whilst there is no US federal law directly requiring it, the CCPA in California as well as GPC opt out settings are applicable in several US states.
Does Google Consent Mode replace a cookie consent banner?
No, this is not a replacement, but it is a more elegant and automated method for users and browsers to specify their consent preferences for certain cookies. This happens automatically in the background.
What is the minimum privacy compliance a small business website should have?
A typical best practice is to have a privacy policy and a cookie policy declaration as an absolute minimum.
When should I implement a full Consent Management Platform?
The answer is pretty much any time you are doing tracking, more than the basic analytics and using retargeting pixels. This is pretty much required for any business in the EU and is recommended for most US businesses. Jurisdiction appropriate settings are important and this is what a Consent Management Platform (CMP) does for you.
Does HIPAA require healthcare websites to have a cookie banner?
No, cookie banners are not required for HIPAA compliance healthcare websites. That does not preclude them, and they are recommended. The presence of a cookie banner does not do anything towards HIPAA compliance.
Can I use remarketing or advertising cookies without user consent?
This is a little bit of a murky area as there are some narrow exceptions but its best practice to consider that advertising cookies must obtain consent. The key is really personalization and tracking. So non targeted advertising cookies are potentially not required to have user consent, but it is best practice to do so.
How do I know which privacy laws apply to my business?
We made this guide to help US based businesses understand some of the cookie consent requirements. That is not a substitute for legal advice which should always be sought on any legal matters. In the US there is a distinct CCPA law in California and a GPC that is required by several states. Using a CMP with appropriate locations and jurisdictions set will help ensure you are compliant.
Do I need a cookie policy if I already have a privacy policy?
Cookie policies and privacy policies are different, although you could argue that cookie use and policy can be covered under the privacy policy. It is generally best to have two distinct policies and notices on your site stating how you use and treat them.
What information should be included in a privacy policy?
In a privacy policy, you should typically declare how you handle information and keep it private. For example, if someone submits some personal information via a form, how are you keeping it private, where is it stored, who has access, is it given to anyone else, it is used for marketing and future sales activity. Basically, how do you handle the data that you collect. With HIPAA this has further requirements and considerations.
What is the difference between a cookie policy and a privacy policy?
The cookie policy is more specific and pertains to the use of cookies on a site, whereas the privacy policy is more general. There are overlaps and arguably cookie policy is a subset of privacy policy, however it is best practice to have both as seperate statements on your site.
Does my website need to support Global Privacy Control (GPC)?
Depending on the jurisdiction you are in and where your site operates the answer may be no. CCPA and GDPR nullify this by extending to an Opt in policy over and above the Opt out policy of GPC. There are several US states that do require GPC. It is best to implement a Consent Management Platform (CMP) and let that handle things appropriately for you.
How do browser privacy settings affect website tracking?
Browser privacy settings can have a significant impact on whether or not websites can track you and to what extent. Possibly more important is your location and the jurisdiction of the website you are using. The most common browser privacy setting is Global Privacy Control (GPC) which operates an Opt out setting and sends it to compliant sites. Browser privacy settings also have significant control over coolies and consent settings.
Will a cookie consent banner reduce my analytics data?
In almost all cases, yes to some extent. The exact extent depends on where you operate and which jurisdiction your site is regulated by. As a rule of thumb we generally guide that in the USA with Global Privacy Control (GPC) you lose about 30% of traffic visibility and with GDPR you lose about 70%. It is always best to use other data sources and do a correlation analysis to understand how impactful it is to your site.
How does GDPR impact Google Analytics tracking?
Fairly significantly, roughly about 70% of tracking visibility is lost when full GDPR consent requirements are implemented. There are alternative analytics tracking solutions that are not as impacted. It is always best to use other data sources and do a correlation analysis to understand how impactful it is to your site.
What happens if I ignore cookie consent and privacy regulations?
There are various financial penalties and potential law suits for failing to comply. Be safe and implement a Consent Management Platform (CMP)
Are cookie consent requirements different for B2B and B2C websites?
Typically not, there is not much delineation between B2B and B2C data, as you are still collecting and storing a person’s data. There are some further nuances on the level of compliance and types of use cases that affect implementation of solutions.
Do e-commerce websites have additional cookie compliance requirements?
Typically yes because of the types of tracking and retargetting that is common with these types of sites. The fact you have an ecommerce site dot explicitly mean higher levels of compliance, its more the use case and operation of typical ecommerce sites that dictatest this.
How do advertising platforms like Google Ads and Meta affect cookie compliance?
These are typically using 3rd part targeted tracking pixels which have the highest bar for consent. Strict opt-in and acceptance is typically required to be compliant. This is best managed by a Consent Management Platform (CMP).
What tracking technologies should I disclose in my privacy policy?
And and all tracking technologies and their use should be specified in applicable privacy and cookie policies.
What is the best cookie consent solution for a small business website?
We use and are fans of Cookie Yes. There are several plugin based and Google Tag Manager (GTM) configurable platforms that give quick and easy set up with good visibility and control over settings.
